First published: Fri Mar 21 2025(Updated: )
Varnish Enterprise before 6.0.13r13 allows remote attackers to obtain sensitive information via an out-of-bounds read for range requests on ephemeral MSE4 stevedore objects.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Varnish Cache | <6.0.13r13 | |
Varnish Cache | =6.0.13-r10 | |
Varnish Cache | =6.0.13-r11 | |
Varnish Cache | =6.0.13-r12 | |
Varnish Cache | =6.0.13-r2 | |
Varnish Cache | =6.0.13-r3 | |
Varnish Cache | =6.0.13-r4 | |
Varnish Cache | =6.0.13-r5 | |
Varnish Cache | =6.0.13-r6 | |
Varnish Cache | =6.0.13-r7 | |
Varnish Cache | =6.0.13-r8 | |
Varnish Cache | =6.0.13-r9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-30347 is classified as a medium-severity vulnerability due to potential data exposure.
To fix CVE-2025-30347, upgrade Varnish Enterprise to version 6.0.13r13 or later.
CVE-2025-30347 affects Varnish Enterprise versions prior to 6.0.13r13.
CVE-2025-30347 is an out-of-bounds read vulnerability that can allow sensitive information to be accessed.
Yes, CVE-2025-30347 can be exploited remotely, allowing attackers to obtain sensitive information.